The €403 million in penalties that Ireland's Data Protection Commission imposed on Google today rests on arguments first put to European regulators in November 2018, when seven consumer groups accused the company of steering Android owners into sharing their whereabouts and then using that information for advertising without a valid legal basis. Set against the findings published today, the complaint shows where the regulator followed the consumer groups, where it went beyond them, and what it has yet to explain.

In Short

In 2018, consumer groups in seven European countries complained that Google pushed people with Android phones into letting it record where they went, and then used that record to show them ads without proper permission. Ireland's privacy regulator decided today that Google did break Europe's data rules in how it handled location information, which matters to anyone in Europe with a Google account or an Android phone and to the advertisers whose targeting and measurement draw on that data. Google now has six months to change how it processes the data, but the regulator has not yet published its full reasoning, so it is not yet possible to say exactly which of the complaint's arguments it accepted.

A template, seven filings

On 27 November 2018, consumer organisations in seven countries said they would file complaints against Google with their national data protection authorities, according to BEUC, the Brussels-based European Consumer Organisation. The seven were Forbrukerrådet in Norway, Consumentenbond in the Netherlands, Ekpizo in Greece, dTest in the Czech Republic, Zveza Potrošnikov Slovenije in Slovenia, Federacja Konsumentów in Poland and Sveriges Konsumenter in Sweden. Others took different routes. Denmark's Forbrugerrådet Tænk planned to report the practices to the Danish data protection body, Germany's vzbv was weighing an injunction, and the Transatlantic Consumer Dialogue intended to raise the matter with the US Federal Trade Commission, according to BEUC.

The document reviewed for this article is the template those filings followed. It carries placeholders where the authority, the consumer organisation and the complainant would be named, uses bracketed pronouns for the data subject, and is undated. It is lodged under Article 80(1) of the GDPR, which allows a non-profit body to act on an individual's mandate, and it names Google LLC, at Amphitheatre Parkway in Mountain View, as the respondent. Its evidence base is the Forbrukerrådet report "Every Step You Take: How deceptive design lets Google track users 24/7", dated November 2018 and attached as the first appendix. Google's privacy policy and terms of service form the second and third.

The complainant described in the template owns an Android smartphone linked to a Google account. The consumer groups asked the authority to examine Google's compliance with Articles 5, 6, 7, 12, 13 and 25 of the regulation, and they aimed at two account settings: Location History and Web & App ActivityLocation Accuracy, the third feature in today's decision, does not appear anywhere in the text.

Google rejected the characterisation at the time. A company spokesman told Reuters that Location History was off by default and could be edited, deleted or paused at any point, according to The Next Web's report of 27 November 2018.

What the settings recorded

Much of the complaint is a close description of the two products as they appeared on Android handsets in 2018. Location History, it says, derived position from GPS, Wi-Fi scanning and Bluetooth scanning, which let Google place a user inside buildings as well as outdoors. Once enabled, the setting collected the mode of transport (walking, driving, riding a tram, entering a vehicle), barometric pressure as a proxy for altitude, Wi-Fi information, GPS coordinates and the device's battery level. Some of this was visible to users in the Location History Timeline. The barometric readings, nearby Wi-Fi hotspots, Bluetooth beacons and battery data were, according to the complaint, collected passively in the background and never displayed.

Web & App Activity worked differently. Most apps did not record location through it, the complaint acknowledges, but Google searches and searches in Google Maps were logged together with the place where the user stood when typing the query. Those records sat in a separate "My Activity" log, kept apart from the Timeline.

What was the data for? The complaint answers with Google's own words, taken from the company's activity controls page: "This data helps Google give you more personalized experiences across Google services, like a map of where you've been, tips about your commute, recommendations based on places you've visited, and useful ads, both on and off Google." The final clause carried the case. Advertising "off Google" extends beyond Search, Maps and YouTube to the third-party sites and apps where Google places ads.

From Mountain View to Dublin

The complaint went to seven authorities, but it did not stay with them. On 22 January 2019, Google Ireland Limited became the data controller for users in the European Economic Area and Switzerland, replacing Google LLC, according to Google's blog post on the change. Google said the change was intended to ease engagement with European authorities through the GDPR's one-stop-shop mechanism and did not alter how its products worked or how it collected data. From that point, the mechanism pointed cross-border complaints about Google's EEA processing towards the Irish authority.

The timing was notable. A day earlier, on 21 January 2019, France's CNIL had fined Google LLC €50 million over Android account creation, a case in which the French authority concluded that the Irish regulator was not the lead authority for that processing, according to Privacy International.

The DPC opened its own inquiry on 4 February 2020, under Section 110 of Ireland's Data Protection Act 2018 and the Article 60 cooperation procedure, according to TechCrunch's report that day. The authority described the concerns it had received as relating to the legality of Google's processing of location data and the transparency surrounding it. The inquiry opened 434 days after the consumer groups went public, and its opening date also closes the window it examined, which runs from 25 May 2018.

The pace drew complaints of its own. When BEUC published a report on barriers to cross-border GDPR enforcement in November 2020, the location complaints were still unresolved two years after filing, according to TechCrunch. Today's decision arrives 2,855 days after the complaints were made public, a gap of seven years and nearly ten months.

One question the DPC statement leaves open concerns the calendar. The inquiry window starts on 25 May 2018, which is 242 days before Google Ireland Limited became the controller under Google's own policy. The decision is addressed to Google Ireland Limited, and the statement does not explain how processing in those earlier months was attributed. The full decision, which the DPC says it will issue in due course, is the document likely to settle it.

Lawfulness and fairness: the core of the case

The DPC found that Google infringed the requirements of lawfulness and fairness in its processing of location data through Web & App Activity and Location History. That is the ground on which the consumer groups spent most of their pages, though they built it without knowing which legal basis Google relied upon. The complaint says it would "preliminary assume" consent for Location History, since the feature required an opt-in. Web & App Activity, switched on by default, pointed either to consent obtained by pressure or to reliance on legitimate interests.

For Location History, the argument rested on the regulation's definition of consent in Article 4(11), which the complaint quotes as "any freely given, specific, informed and unambiguous indication". The consumer groups argued that none of the four elements held.

Repetition was the most concrete allegation. Users who declined Location History during setup, according to the complaint, "must decline the activation of the setting at least four times when using different services that are preinstalled on Android phones; in Google Assistant, Google Maps, Google Search App, and Google Photos." Bundling came next. A user who simply wanted photographs grouped by place had to switch on Location History in full, including its advertising uses. The complaint called this a bundled "take it or leave it" option, and said enabling Google Assistant carried the same consequence.

Interface design ran through the rest. The Android setup sequence, the complaint contends, was built so that a user following the natural click-flow ended up consenting; the advertising use appeared only behind a "Learn more" link; and attempts to pause the setting brought vague warnings about lost functionality. The Forbrukerrådet research described these techniques as deceptive design, a family of practices now more commonly discussed as dark patterns.

Market power featured too. The complaint cited Recital 43 of the GDPR for the principle that consent is not a valid ground where there is a clear imbalance between the parties, and argued that "Google is clearly in a dominant position when 85% of global smart phones are running on the Android operating system, which is a Google product". The figure, credited to IDC, is the complaint's own; the DPC statement makes no reference to market share. Google's position in Android has also been tested under competition law, where the Court of Justice of the European Union dismissed Google's appeal against the €4.125 billion Android fine in July 2026.

A point in Google's favour sits in the complaint's own exhibits. Its screenshot of the Android account setup page shows Location History with "Don't save my Location History to my Google Account" already selected, which is consistent with the company's position that the feature was off by default. The same series of screenshots shows Web & App Activity set the opposite way, with "Save my Web & App Activity to my Google Account" pre-selected.

Web & App Activity, switched on at the start

That default was the centre of the second argument. The complaint states that Web & App Activity was enabled by default when an account was created and cites the GDPR and Article 29 Working Party guidance for the rule that "Pre-ticked boxes or any other method of consent by default are not to be used." At setup, the feature was described as saving "your searches, Chrome browsing history and activity from sites and apps that use Google services". That location data was involved became clear, the complaint says, only after tapping "More options" and then "Learn more". Pausing the setting produced a warning that users "may stop seeing more relevant search results or recommendations that you care about".

The consumer groups then tried to close off the two alternatives. Performance of a contract under Article 6(1)(b) failed, they argued, because Google never claimed the processing was necessary to deliver its services, and the fact that a user could pause the setting suggested it was not. Legitimate interests under Article 6(1)(f) failed the balancing test: collection happened without any user interaction, data was kept on a seemingly indefinite basis, it fed advertising, and users had no reasonable expectation of any of it. The complaint cited the Article 29 Working Party's Opinion 06/2014, which held that "opt-in consent would almost always be required [...] for tracking and profiling for purposes of direct marketing, behavioural advertisement, location-based advertising or tracking-based digital market research".

European practice has moved towards that view since. In December 2022 the European Data Protection Board found contract unsuitable as a legal basis for Meta's behavioural advertising, and on 27 October 2023 it instructed the DPC to ban such processing on the basis of contract and legitimate interest across the European Economic Area. IAB Europe's Transparency and Consent Framework, the specification many consent management platforms implement, withdrew legitimate interest as a basis for its profiling and personalisation purposes in version 2.2, released on 16 May 2023. And an EDPB-commissioned review of 62 one-stop-shop decisions and five binding decisions on legitimate interest, adopted between December 2018 and June 2025, found controllers systematically underestimating what the balancing test requires.

Which legal basis Google actually relied on for each purpose, and on which of these arguments the DPC decided, remains unstated. The statement says only that the processing breached the principles of lawfulness and fairness.

Transparency across three features

The second finding, breaches of Google's transparency obligations in all three features, maps onto an argument the consumer groups pitched at the level of the privacy policy. According to the complaint, Google listed four of the six legal bases in Article 6 - consent, legitimate interest, provision of a service and legal obligations - with examples under each. The policy said Google asked for consent to provide personalised services such as ads, yet it also listed advertising among the company's legitimate interests. That left it unclear, the complaint argued, which basis applied to behavioural targeting, and the information was not given during account setup either.

The complaint presents the problem as a long-running one. It says the Article 29 Working Party raised the same concern when Google merged the privacy policies of its services in 2012, and that the company continued to provide unclear and incomplete information after the GDPR took effect. It also takes issue with a single adjective. The setup screen described Location History as saving a "private map" of where the user went, prompting the complaint to ask: "What does 'private' mean in this context, when Google has access to all the data and can use it for other purposes beyond the creation of the map?"

France had already acted on closely related screens. The CNIL's €50 million penalty in January 2019 was imposed for lack of transparency, inadequate information and lack of valid consent regarding ads personalisation, following group complaints filed by noyb and La Quadrature du Net on 25 and 28 May 2018, according to the EDPB's summary of the French decision. The CNIL found information diluted across several documents and consent that was neither specific nor unambiguous, with the relevant options hidden behind a "More options" button. The boxes governing ad personalisation were pre-checked by default, according to law firm Hunton Andrews Kurth's account of the ruling. The same account-creation flow drew a second French penalty when the CNIL fined Google €325 million on 1 September 2025, in part because users creating an account were presented with an imbalanced choice over advertising cookies.

Retention: in the facts, not in the requests

The retention finding, which covers Web & App Activity and Location History, is the one the consumer groups did not formally seek. Their list of requests asks the authority to rule on legal basis and information, on the Article 7 consent conditions, on legitimate interests, and on whether Google's design patterns were compatible with Articles 5(1)(a) and 25. Storage periods appear only in the factual narrative and the balancing argument. "Location History data is seemingly retained indefinitely if the user does not manually delete it," the complaint says, adding that deleting historical data was a separate process from pausing the feature.

The DPC nonetheless treated retention as a distinct infringement. Deputy Commissioner Graham Doyle said keeping users' location data for longer than necessary made their loss of control over it worse, according to the DPC.

Google's defence engages this point most directly. A company spokesperson said the case concerns historical policies that have since been updated, and that from 2019 onwards Google significantly changed its practices and added tools that make location data simpler to manage, according to NewsIreland.EU. Those changes began after the complaint was filed but partly inside the window the inquiry examined. Whether they satisfy a six-month compliance order framed around the 2018 to 2020 products is something the published statement does not address.

Location Accuracy: outside the complaint's text

The fourth finding concerns a feature the consumer groups never named. Location Accuracy is part of the Android operating system rather than an account setting, and it lets a device fix its position more precisely than GPS alone would allow, according to the DPC. It is available to Android users whether or not they hold a Google Account. The DPC found that Google breached its accountability obligations because it could not demonstrate that its processing of personal data in Location Accuracy complied with the principle of lawfulness, fairness and transparency.

The closest the complaint comes is a passing reference to the Android control that turns device location services on and off, which it cites as evidence that Google could personalise services without location data. The feature's presence in the decision reflects the reach of an own-volition inquiry, in which the authority, not the complainant, sets the scope. The distinction between complaint-based and own-volition inquiries was argued by Meta before Ireland's High Court in a separate case, and Justice Siobhán Phelan rejected all of Meta's grounds on 21 May 2026, holding that Article 83 requires fines to account for the number of data subjects affected however an inquiry begins.

What the consumer groups asked for

Section D of the complaint set out four questions: whether Google had a lawful basis for processing location data, particularly for advertising, and whether it told users which basis it used; whether the Article 7 conditions for valid consent were met; whether legitimate interests could serve as a basis; and whether Google's design choices were compatible with fairness, transparency and data protection by design and by default. It then asked the authority to stop any unlawful processing, "notably those operations related to the use of such data for advertising purposes", and to impose "an effective, proportionate and deterrent fine".

On the first three, the DPC's lawfulness and transparency findings give the consumer groups much of what they sought, subject to the reasoning still to be published. On the fourth, the statement is silent: it does not mention Article 25, design patterns or the setup screens. The complaint also asked that the matter go to the European Data Protection Board if appropriate. The DPC thanked its peer supervisory authorities for their cooperation and did not describe any objections or a referral to the Board.

The fine factors the complaint proposed were specific. It asked the authority to weigh the number of users affected, potentially anyone with an Android phone or a Google account; the sensitivity of location data; Google's status as what it called a "repeat offender"; the financial gains from processing personal data for advertising; and the company's dominant market power. The DPC has not broken the €403 million down by infringement or explained how it was calculated.

A sense of scale comes from Article 83 of the GDPR, which caps fines for breaches of the basic principles at €20 million or 4% of an undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher. In its separate Hive inquiry, the DPC told Meta that the cap would be calculated by reference to the Meta group as a whole rather than the Irish subsidiary, according to the High Court judgment. Alphabet reported annual revenues above $400 billion for the first time for 2025. Measured against that figure, the penalty, about $463 million according to Reuters, amounts to about 0.1%, while a group-level cap would sit above $16 billion. It is nonetheless the fourth-largest fine the DPC has imposed, out of more than €4 billion it has levied since becoming lead regulator for most large US technology firms, according to Reuters.

The complainants' response was mixed. BEUC's director general Agustín Reyna welcomed the decision but said the time taken was out of proportion to the seriousness of the infringement, warning that late enforcement can be as harmful as none, according to NewsIreland.EU. BEUC also said Google had made changes globally after the original complaint, but that further concerns had prompted a second complaint in 2022. Finn Myrstad, digital policy director at the Norwegian Consumer Council, described the ruling as an important milestone, according to Invezz.

The Norwegian council has been a recurring source of such cases. Its 2020 complaint against Grindr, which covered the sharing of HIV status and location data with advertisers, ended in a 65 million kroner fine that Oslo District Court upheldin July 2024. On 3 June 2026 it joined noyb in a complaint against Schibsted's pay-or-okay model. BEUC, for its part, coordinated national complaints to data protection authorities over Meta's consent-for-ads model in February 2024.

Why the location question reaches advertisers

The advertising relevance is written into the complaint's central quotation. "Useful ads, both on and off Google" describes location data flowing into targeting across Google's own properties and its network. Doyle made the same connection today, saying users could have been unaware that their location was being used to influence them with ads or to infer their interests, according to the DPC.

Measurement depends on the same signals. Google's store visits conversions, its implementation of footfall attribution, are modelled from signed-in users with location history enabled who interact with an ad and later visit a business, with Google extrapolating from those observed cases to the wider exposed audience. Google's consumer product has since shifted: Maps Timeline, first detailed in December 2023 and rolled out through 2024, moved history storage onto the device and cut default retention from 18 months to three. Google's advertising documentation still describes an account-level location history opt-in, and the company has not publicly reconciled the two.

American litigation has attacked the same settings from the other end. A San Francisco jury ordered Google to pay $425.7 million on 3 September 2025 in a class action over data gathered after users switched Web & App Activity off. Google settled a case for $62 million in May 2024 over allegations that it tracked users after Location History was turned off, and Texas secured a $1.375 billion privacy settlement that included Location History claims. Those cases asked whether switching the settings off actually stopped collection. The European complaint asked a different question: how the settings came to be switched on in the first place, and what users were told when they were.

Durability is the remaining uncertainty. An analysis by Alliance Risk found that nearly 40% of the €7.1 billion in GDPR fines issued since 2018 had been annulled or were under active challenge. In March 2026 a Luxembourg court annulled Amazon's €746 million fine, a penalty imposed because interest-based advertising lacked a valid legal basis, on the grounds that the regulator had not assessed fault or justified why a fine was the right corrective measure. The Google statement reported today does not say whether the company will challenge the DPC's decision.

If the six-month compliance period runs from today, it would end on 21 March 2027. The statement does not specify the starting point.

Timeline

Summary

Who: Ireland's Data Protection Commission, through Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney, against Google Ireland Limited. The inquiry followed complaints coordinated by BEUC and filed by consumer organisations in Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland and Sweden, built on research by Forbrukerrådet. The complaint template named Google LLC; Google Ireland Limited became the EEA data controller on 22 January 2019.

What: A final decision imposing fines totalling €403 million and a six-month compliance order, with findings on lawfulness and fairness in Web & App Activity and Location History, transparency in all three examined features, retention in Web & App Activity and Location History, and accountability in Location Accuracy. The 2018 complaint argued that consent for Location History was not freely given, specific, informed or unambiguous, that Web & App Activity was enabled by default, and that neither contract nor legitimate interests could justify using location data for advertising. It did not mention Location Accuracy and did not formally request a retention finding.

When: The DPC made the decision public today, 21 September 2026. The complaints were made public on 27 November 2018, the inquiry opened on 4 February 2020, and the period examined runs from 25 May 2018 to 4 February 2020.

Where: The decision was taken in Dublin by Google's lead supervisory authority and concerns processing of the personal data of Google account holders and Android users across the European Economic Area.

Why: According to the DPC, Google's failures meant people could have been unaware that their location was being used to influence them with ads or to infer their interests, and keeping the data longer than necessary deepened the loss of control. The complaint traced that outcome to setup screens that pre-selected Web & App Activity, repeated prompts to enable Location History, bundled features, and a privacy policy that did not say which legal basis covered advertising. For advertisers, the same settings feed Google's location-based targeting and store visits measurement.